Critical severityNVD Advisory· Published Jul 14, 2019· Updated Aug 4, 2024
CVE-2019-13589
CVE-2019-13589
Description
The paranoid2 gem 1.1.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.1.5.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- paranoid2 gem/paranoid2 gemdescription
- ghsa-coords
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-4g4c-8gqh-m4vmghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-13589ghsaADVISORY
- www.securityfocus.com/bid/109281ghsavdb-entryx_refsource_BIDWEB
- github.com/rubygems/rubygems.org/issues/2051ghsax_refsource_MISCWEB
- github.com/rubysec/ruby-advisory-db/blob/master/gems/paranoid2/CVE-2019-13589.ymlghsaWEB
- rubygems.org/gems/paranoid2/versionsghsax_refsource_MISCWEB
- snyk.io/vuln/SNYK-RUBY-PARANOID2-451600ghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.